UNC1151 Ghostwriter Phishing Domain DNS/HTTP Activity (T1566.002)

Detects DNS queries and network connection attempts to a set of known malicious domains associated with the threat actor UNC1151 (Ghostwriter). This rule monitors both DNS resolutions and direct network connection attempts to these indicators of compromise (IOCs), which are commonly used in spearphishing campaigns.